CVE-2025-44182: XSS
Published May 15, 2025
·Updated
Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the vehiclename, modelnumber, regnumber, vehiclesubtype, chasisnum, enginenumber' in the /admin/edit-vehicle.php component. This allows attackers to execute arbitrary code.
Affected Software
2 affected components
Phpgurukul Vehicle Record Management System
Anujk305 Vehicle Record Management System=1.0
Event History
May 15, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-44182?
CVE-2025-44182 has a high severity due to its potential for Cross Site Scripting (XSS) attacks.
2
How do I fix CVE-2025-44182?
To fix CVE-2025-44182, sanitize and validate all user inputs in the /admin/edit-vehicle.php component.
3
What type of vulnerability is CVE-2025-44182?
CVE-2025-44182 is classified as a Cross Site Scripting (XSS) vulnerability.
4
What components are affected by CVE-2025-44182?
CVE-2025-44182 affects the /admin/edit-vehicle.php component of Phpgurukul Vehicle Record Management System v1.0.
5
Can CVE-2025-44182 allow code execution?
Yes, CVE-2025-44182 allows attackers to execute arbitrary code through XSS.